CVE-2006-2866

DotClear <1.2.4 - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1869

Scores

EPSS 0.1185
EPSS Percentile 93.8%

Details

Status published
Products (4)
dotclear/dotclear 1.2.1
dotclear/dotclear 1.2.2
dotclear/dotclear 1.2.3
dotclear/dotclear 1.2.4
Published Jun 06, 2006
Tracked Since Feb 18, 2026